Report it privately through GitHub's security advisories. Do not open a public issue or pull request for it.
Include what you did, what happened and the version you ran. A patch file or bundle that triggers it is the most useful thing to attach.
The latest release. Fixes land on main and ship in the next release.
Flyback opens files and loads code that other people write, so these are the places a flaw matters:
- A patch, bundle or sample that crashes, hangs or exhausts memory when opened, or writes outside its folder.
- A plugin that loads without being allowed, or that reaches a stored API key (ADR-0158).
- An update that installs without its signature verifying (ADR-0088).
- A flaw in the preset site: injection, an unchecked upload, or one user reaching another's data.
- A secret committed to the repository.
Not a vulnerability: a patch that is slow or loud, or a crash that needs you to run a plugin you chose to allow.